US8539544B2

Method of optimizing policy conformance check for a device with a large set of posture attribute combinations

Summary by NHIP

Policy Conformance Check Method

The method receives a client certificate containing a timestamp and policy tag, then compares these against stored timestamps to grant network access. Distinctive steps include storing policy tags in priority order, directing quarantine access if the certificate timestamp predates a critical tag timestamp, and triggering remediation when the certificate timestamp predates the tag timestamp.

Claim Score by NHIP

Read claim 1, the broadest

Abstract

A method, apparatus, and electronic device for conforming integrity of a client device 106 are disclosed. A memory 1100 may store a policy tag 404 associated with a subgroup of a group of policies 1102 and having a tag timestamp. A network interface 1060 may receive the certificate of health 300 from the client device 106. A processor 1010 may extract from the certificate of health a certificate timestamp 302 and a policy tag 304. The processor 1010 may access the tag timestamp. The processor 1010 may execute a comparison of the certificate timestamp 302 with the tag timestamp. The network interface 1060 may grant access to a network 104 based in part upon the comparison.

US8539544B2, drawing sheet 1
Sheet 1 of 13

Term

4.3 yearsleft in the term

Expires 14 January 2031, including 959 days of term adjustment.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

19 claims: 3 independent, 16 dependent

  1. 1
    Broadest claimClaim Score 71, broad(NHIP)A method for conforming integrity of a client device, comprising:receiving a certificate of health from the client device;extracting from the certificate of health a certificate timestamp and a policy tag associated with a subgroup of a group of policies;storing multiple policy tags in a priority order;accessing a tag timestamp associated with the policy tag;executing a comparison of the certificate timestamp with the tag timestamp;and granting access to a network based in part upon the comparison.
  2. 8
    An access server for conforming integrity of a client device, comprising:a memory that stores a policy tag associated with a subgroup of a group of policies and a tag timestamp, wherein the memory stores multiple policy tags in a priority order;a processor that extracts from a certificate of health a certificate timestamp and the policy tag, accesses the tag timestamp, and executes a comparison of the certificate timestamp with the tag timestamp;and a network interface that receives the certificate of health from the client device and grants access to a network based in part upon the comparison.
  3. 15
    A system comprising:a client device to securely access a network, comprising: a memory that stores a certificate of health containing a policy tag associated with a subgroup of a group of policies and a certificate timestamp;and a transceiver that transmits the certificate of health to the network and accesses the network based in part upon a comparison of a tag timestamp associated with the policy tag and the certificate timestamp;and an access server comprising: a memory that stores multiple policy tags in a priority order.